In a few years, we’re going to get a killer docudrama about ShinyHunters, the hacking group that’s been responsible for breaches at companies like ADT, Canvas, and Vimeo, as well as most recently, the FBI. The drama continued this week, when the FBI fired back at ShinyHunters, claiming to have had a hand in the arrest of a member of the group in the Netherlands. That said, statements from ShinyHunters remain defiant, and since the arrest of an alleged member took place in the Netherlands, it’s unclear what, if anything, the FBI had to do with it.
To ShinyHunters’ credit, the group never did say it planned to leak the data it obtained from the FBI. Even in its announcement about data capture, it noted that its issue with the FBI was rooted in an alert the agency published in May, which categorized the group as scammers and claimed it uses harassment and false claims to pressure its victims. The gray hat in me is watching this whole affair with a raised eyebrow.
In other news, remember back in September when more than 153 million driver’s licenses were lost in a breach? Well, now the company responsible for the missing data says the hackers who got it had access to its internal systems for five months, and it's still unclear how many people were actually affected and how much data was lost. The class-action lawsuits are already rolling in.
And because we’ll never get through a week in cybersecurity without another AI-related debacle, Meta’s shiny new AI agent, Muse, rocketed to the top of app stores when it launched, but as people started using it, the security issues surfaced quickly. In one case, a user told Muse to handle his Facebook Marketplace account, and the agent went ahead and approved sales without his knowledge and even doxxed him, telling a buyer to come to his house to get their item, but didn’t tell him when the buyer arrived, and then told him after the fact that the buyer was angry and left a bad review. That’s bad enough, but the agent also launched with a zero-day vulnerability that, luckily, has been patched. Amazon has blocked Muse entirely.
That's not all! Let’s see what else is going on in the infosec world this week.
Fake iPhone Duo Preorder Scam Triggers DarkSword Attack
If you’re lining up for an iPhone Duo, keep your guard up for scams. In this case, the Malwarebytes blog caught wind of a new one, designed to look almost exactly like an actual Apple website, complete with the company's branding. The site promises a $500 voucher for preordering an iPhone Duo, and even has a countdown timer designed to make you think that you have limited time to sign up for the offer. But here’s the thing: Just by opening the page, you’ve already fallen for it.
The site has the DarkSword exploit embedded, which immediately scans your device for cryptocurrency wallets and any saved passwords in the keychain, and even attempts to access messages, call history, voicemail, contacts, location data, and more. The payload from the site even tries to cover its tracks by deleting any logs that could point to the infection, and it calls home regularly for more instructions on what data to try to capture.
Of course, DarkSword only works on older devices or devices running older versions of iOS, and is a Safari-only exploit, so if you try to visit the site using any other browser, it tries to get you to switch to Safari by claiming your browser isn’t supported. But thankfully, if you’ve updated your iOS device (yes, even the one you may want to replace with an iPhone Duo) or use an alternative browser, you should be OK.
North Korea Suspected in $351 Million Bitget Crypto Heist
If it wasn’t clear that cryptocurrency is the preferred method of moving money for scammers and hackers around the world, it should be now. Don’t get me wrong, we’re all for private, anonymous methods of payment, but it’s hard to keep reading reports of hackers either robbing people’s crypto wallets or stealing from exchanges without that being the takeaway.
And speaking of exchanges, SecurityWeek reports that Bitget was the victim of an attack that ended up with more than $351 million in digital assets across multiple cryptocurrencies stolen from its members, although Gracy Chen, CEO of Bitget, says the company is working on it and has already frozen some of the wallets it believes belong to attackers. Chen says the attack patterns are consistent with those of North Korean state-sponsored hackers, and while the company hasn’t yet determined how the hackers gained access to Bitget’s systems, it's working with security firms to do so. As for the money itself, aside from the frozen wallets, it may already be gone. Such is the nature of cryptocurrency.
Your Car’s App Is Probably Telling Big Tech Who You Are and Where You Go
When you open up your car’s app to connect to it or unlock it remotely, you don’t expect that you’re telling advertisers where you’re driving and what you’re doing, but that’s exactly what could be happening. The Malwarebytes blog notes that researchers from Northweastern University tested 21 cars across 19 brands, and 30 different car companion apps, and found that both the apps and the vehicles themselves frequently contacted third-party domains, including advertisers and trackers, with 19 of the 21 vehicles sending data to at least one third party and seven of the 30 companion apps sending personally identifiable data to third-party trackers. Worse, five of those apps sent personally identifiable data and the vehicle’s VIN to trackers. This isn’t the first time car companies have been called out on privacy, either: Back in 2023, we covered a Mozilla report sounding the alarm on this topic, and earlier this year, the FTC fined GM for its data collection practices.
As the Malwarebytes blog notes, a connected vehicle contacting its manufacturer isn’t an issue in itself, since updates, safety alerts, and navigation all require internet access. But it’s when the vehicle and its apps collect information about where you drive, how you use the apps, and even identifying data that can tell advertisers things like where you go, where you live, where you seek medical care, and more, that it becomes pretty problematic. It’s even worse when you don’t really have a way to opt out of that tracking, and even if you do, the apps scare you with warnings of “reduced functionality, serious damage, or inoperability,” which is enough to deter you from interfering with the car you need to get to work every day.
Ask Our Expert: Is Remote Access Software Safe to Use?
Do you have a question about online privacy or security? I'm here to help! You can submit your question here, and I may answer it in an upcoming SecurityWatch column and newsletter. If you're not subscribed to the newsletter, head here to sign up, and check back each week for the latest updates from PCMag's security team. Now, on to this week's question!
Phil H asks: “Has anyone tested the security of various remote access programs (such as TeamViewer, ShowMyPC, etc.). Are they safe?”
Hi Phil, thanks for your question! This is a great one, because some remote access trojans use the same technology as trustworthy remote access software. In short, professional remote access software is generally safe, but you should still use it with caution.
Each of our remote access software reviews includes a section that asks, “Is this tool safe to use?” in which we point out the app's security features, whether your sessions are end-to-end encrypted, and whether the app supports multi-factor authentication.
The best remote access tools encrypt their connections and require that you use strong passwords and multi-factor authentication to secure your accounts. They’ll even have options baked in to reject any connection requests that you don’t personally approve, or from anyone not in your allowed connections list. Some apps are very proud of their security measures, and those are the ones we recommend highly. For example, TeamViewer promotes its end-to-end 256-bit AES encryption. But you still have to do your homework and check an app’s website for details on how it keeps your data safe and best practices for using it properly.
In our reviews, we always remind readers not to install remote access software if someone you don’t know or trust asks you to, and to never give out your session credentials to someone you didn’t initiate a connection with. One of the best features of remote access software is that you can set it up so you or someone you trust can connect to a device that’s not currently in use, which definitely makes troubleshooting a family PC from across the country easier. However, it’s also worth remembering that convenience comes with a security trade-off.
My advice? Pick a well-known, trustworthy tool, and then do what I do when I need to troubleshoot my father’s PC from hundreds of miles away: Send a quick text to say, “Can you fire up the app for me?” and connect once he replies. When you're finished, follow up with a text that says, "All done! I shut the PC down,” since most of them allow you to turn off the computer once you disconnect.
About Our Expert
I've been writing and editing stories for almost two decades that help people use technology and productivity techniques to work better, live better, and protect their privacy and personal data. As managing editor of PCMag's security team, it's my responsibility to ensure that our product advice is evidence-based, lab-tested, and serves our readers.
I've been a technology journalist for close to 20 years, and I got my start freelancing here at PCMag before beginning a career that would lead me to become editor-in-chief of Lifehacker, a senior editor at The New York Times, and director of special projects at WIRED. I'm back at PCMag to lead our security team and renew my commitment to service journalism. I'm the author of Seen, Heard, and Paid: The New Work Rules for the Marginalized, a career and productivity book to help people of marginalized groups succeed in the workplace.
- ShinyHunters Hits the FBI, Fake LastPass Installers, and a $459M Google Fine: This Week's Cybersecurity Chaos
- How Did AI Send 1M Scams in 3 Days? 7 Brutal Security Stories Making Headlines This Week
- A Meta Exec's 150-Porn-Downloads-a-Day Habit, a 23-Year Botnet Bust, and $1M Phone Unlocks
- SpaceX AI Weaponized, 153K Driver's Licenses Leaked, and GTA 6 Subpoenas: This Week's Security Scandals
- Don't Click the GTA 6 Demo, Don't Trust the Flirty DM: This Week's Cybersecurity Survival Guide
- More from Alan Henry
(Credit: Getty Images)